Skip to main content

Subprocessor List

Last updated: January 15, 2026

Subprocessor List

Document owner: Chief Privacy Officer (CPO) Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Continuous updates with 30-day customer notification Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions

TermDefinition
SubprocessorA third party engaged by Acme Cloud to Process Customer Personal Data on behalf of Customer
Infrastructure SubprocessorA subprocessor providing cloud hosting, content delivery, or core infrastructure services
Functional SubprocessorA subprocessor providing application functionality such as support, communication, or analytics
Security SubprocessorA subprocessor providing security monitoring, threat detection, or incident response capabilities
Customer Personal DataPersonal Data processed by Acme Cloud on behalf of Customer pursuant to the Agreement
ProcessingAny operation performed on Personal Data including collection, storage, use, transmission, and deletion
Data ResidencyThe geographic location where Customer Personal Data is stored at rest
Data TransitGeographic locations through which Customer Personal Data may pass during transmission
SOC 2Service Organization Control 2 audit attestation
ISO 27001International standard for information security management systems
DPAData Processing Agreement governing subprocessor's data protection obligations
SCCStandard Contractual Clauses for international data transfers
DPFData Privacy Framework (EU-US, UK Extension, Swiss-US)
BAABusiness Associate Agreement for HIPAA-covered data
PCI DSSPayment Card Industry Data Security Standard
Transfer MechanismLegal basis for international data transfers (DPF, SCCs, adequacy)

Scope and Applicability

1.1 Document Purpose

This document lists all third-party subprocessors engaged by Acme Cloud, Inc. to Process Customer Personal Data. It is provided to fulfill Acme Cloud's obligations under:

RegulationRequirementDPA Reference
GDPR Article 28(2)Prior authorization for subprocessor engagementSection 5
UK GDPR Article 28(2)Same as GDPRSection 5
LGPD Article 39Subprocessor disclosureSection 5
CCPA/CPRAService provider disclosureSection 11
SCCs Clause 9Subprocessor notificationSection 10

1.2 Subprocessor Categories

Acme Cloud engages subprocessors in the following categories:

CategoryDescriptionData Processed
InfrastructureCloud hosting, storage, CDNAll Customer Personal Data
DatabaseManaged database servicesAll Customer Personal Data
SecurityMonitoring, threat detection, vulnerability managementTechnical data, security logs
CommunicationEmail, messaging, notificationsContact information, message content
SupportHelp desk, customer successSupport interaction data
AnalyticsProduct analytics, error trackingUsage data, technical data
PaymentPayment processing, billingBilling contact, payment tokens
AuthenticationIdentity verificationAuthentication credentials

1.3 Data Processing Scope

Processing ActivitySubprocessor Categories InvolvedCustomer Personal Data Types
Platform hostingInfrastructureAll Customer Personal Data
Data storageInfrastructure, DatabaseAll Customer Personal Data
Content deliveryInfrastructureCached content, session data
Security monitoringSecurityTechnical logs, access patterns
Email notificationsCommunicationEmail addresses, notification content
Customer supportSupportSupport tickets, contact information
Product analyticsAnalyticsPseudonymized usage data
Error trackingAnalyticsError context, user identifiers
BillingPaymentBilling contact, subscription data
Single sign-onAuthenticationSSO tokens, user identifiers

Infrastructure Subprocessors

2.1 Amazon Web Services (AWS)

AttributeDetails
Legal EntityAmazon Web Services, Inc.
HeadquartersSeattle, Washington, USA
Processing LocationsUS (us-east-1, us-west-2), EU (eu-west-1, eu-central-1), UK (eu-west-2), APAC (ap-southeast-1, ap-northeast-1)
Customer Data ResidencyPer customer selection (US, EU, UK, APAC)
Services UsedEC2, RDS, S3, Lambda, SQS, SNS, KMS, Secrets Manager, CloudFront, Route 53
Processing PurposeInfrastructure hosting, compute, storage, database, secrets management
Data Types ProcessedAll Customer Personal Data
Security CertificationsSOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, PCI DSS, FedRAMP, HIPAA
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusAWS Data Processing Addendum incorporated
BAA AvailableYes
Engagement DateJanuary 2022
Review DateJanuary 2026 (annual)

AWS Services Detail:

ServicePurposeData Processed
Amazon EC2/ECSApplication computeTransient processing
Amazon RDSPrimary databaseAll persistent data
Amazon S3Object storage, backupsDocuments, attachments, backups
Amazon KMSEncryption key managementEncryption keys (metadata only)
Amazon Secrets ManagerSecrets storageApplication secrets
Amazon CloudFrontContent deliveryCached static content
Amazon SQS/SNSMessage queuingJob payloads
Amazon Route 53DNS managementNo Personal Data

2.2 Cloudflare

AttributeDetails
Legal EntityCloudflare, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsGlobal edge network (250+ cities)
Customer Data ResidencyCustomer data not persistently stored (transit only)
Services UsedCDN, WAF, DDoS protection, DNS, SSL
Processing PurposeContent delivery, security, performance optimization
Data Types ProcessedRequest metadata, cached content (transient)
Security CertificationsSOC 2 Type II, ISO 27001, PCI DSS
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusCloudflare DPA incorporated
BAA AvailableYes
Engagement DateMarch 2022
Review DateMarch 2026 (annual)

2.3 Neon

AttributeDetails
Legal EntityNeon, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsAWS regions per customer selection
Customer Data ResidencyFollows Acme Cloud AWS region selection
Services UsedServerless PostgreSQL
Processing PurposeDatabase services, data storage
Data Types ProcessedAll Customer Personal Data in database
Security CertificationsSOC 2 Type II
Transfer MechanismEU-US DPF, SCCs
DPA StatusNeon DPA incorporated
BAA AvailableUpon request
Engagement DateJune 2024
Review DateJune 2026 (annual)

Security Subprocessors

3.1 Datadog

AttributeDetails
Legal EntityDatadog, Inc.
HeadquartersNew York, New York, USA
Processing LocationsUS (us-east-1), EU (eu-west-1)
Customer Data ResidencyUS for all customers (security data only)
Services UsedInfrastructure monitoring, APM, Log Management, SIEM
Processing PurposeSystem monitoring, security event correlation, alerting
Data Types ProcessedTechnical logs, performance metrics, security events
Security CertificationsSOC 2 Type II, ISO 27001, HIPAA, PCI DSS
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusDatadog DPA incorporated
BAA AvailableYes
Engagement DateJanuary 2023
Review DateJanuary 2026 (annual)

Data Minimization Controls:

ControlImplementation
PII maskingAutomated masking of email, names, identifiers in logs
Retention limits30-day hot, 90-day cold for security logs
Access controlsRole-based access limited to Security team
EncryptionTLS in transit, AES-256 at rest

3.2 CrowdStrike

AttributeDetails
Legal EntityCrowdStrike, Inc.
HeadquartersAustin, Texas, USA
Processing LocationsUS (primary), EU (available)
Customer Data ResidencyUS for corporate endpoints (no Customer Personal Data)
Services UsedFalcon Endpoint Protection, Threat Intelligence
Processing PurposeEndpoint detection and response, malware protection
Data Types ProcessedEndpoint telemetry from Acme Cloud corporate devices only
Security CertificationsSOC 2 Type II, ISO 27001, FedRAMP
Transfer MechanismEU-US DPF, SCCs
DPA StatusCrowdStrike DPA incorporated
BAA AvailableYes
Engagement DateApril 2023
Review DateApril 2026 (annual)

3.3 Snyk

AttributeDetails
Legal EntitySnyk Limited
HeadquartersBoston, Massachusetts, USA
Processing LocationsUS, EU
Customer Data ResidencyN/A (code analysis only)
Services UsedDependency scanning, container scanning
Processing PurposeVulnerability detection in code dependencies
Data Types ProcessedSource code metadata, dependency lists (no Customer Personal Data)
Security CertificationsSOC 2 Type II, ISO 27001
Transfer MechanismEU-US DPF, SCCs
DPA StatusSnyk DPA incorporated
BAA AvailableN/A
Engagement DateFebruary 2023
Review DateFebruary 2026 (annual)

Communication Subprocessors

4.1 Resend

AttributeDetails
Legal EntityResend, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsUS
Customer Data ResidencyUS (email delivery infrastructure)
Services UsedTransactional email delivery
Processing PurposeSending platform notifications, alerts, reports
Data Types ProcessedEmail addresses, notification content
Security CertificationsSOC 2 Type II
Transfer MechanismEU-US DPF, SCCs
DPA StatusResend DPA incorporated
BAA AvailableUpon request
Engagement DateSeptember 2024
Review DateSeptember 2026 (annual)

Email Processing Details:

Email TypePersonal DataRetention
Account verificationEmail address30 days
Password resetEmail address24 hours
Platform notificationsEmail address, notification content30 days
Scheduled reportsEmail address, report data30 days

4.2 Twilio

AttributeDetails
Legal EntityTwilio Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsUS (primary), EU (available)
Customer Data ResidencyUS for SMS processing
Services UsedSMS notifications (optional, Enterprise feature)
Processing PurposeSMS alerts, MFA verification codes
Data Types ProcessedPhone numbers, message content
Security CertificationsSOC 2 Type II, ISO 27001, HIPAA
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusTwilio DPA incorporated
BAA AvailableYes
Engagement DateJuly 2023
Review DateJuly 2026 (annual)

4.3 Slack (Salesforce)

AttributeDetails
Legal EntitySalesforce, Inc. (Slack Technologies, LLC)
HeadquartersSan Francisco, California, USA
Processing LocationsUS, EU
Customer Data ResidencyPer workspace configuration
Services UsedSlack integration (optional customer feature)
Processing PurposeCustomer-configured Slack notifications
Data Types ProcessedNotification content configured by Customer
Security CertificationsSOC 2 Type II, ISO 27001, HIPAA
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusSalesforce DPA incorporated
BAA AvailableYes
Engagement DateOctober 2023
Review DateOctober 2026 (annual)

Support Subprocessors

5.1 Intercom

AttributeDetails
Legal EntityIntercom R&D Unlimited Company
HeadquartersDublin, Ireland
Processing LocationsUS, EU
Customer Data ResidencyUS (with EU data hosting available)
Services UsedIn-app messaging, help center, customer support
Processing PurposeCustomer communication, support ticket management
Data Types ProcessedUser identifiers, email, support conversations
Security CertificationsSOC 2 Type II, ISO 27001, HIPAA
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusIntercom DPA incorporated
BAA AvailableYes
Engagement DateJanuary 2023
Review DateJanuary 2026 (annual)

Support Data Processing:

Data TypePurposeRetention
User emailSupport identificationActive + 3 years
Conversation historySupport context3 years
User metadataPersonalizationActive + 3 years
Attached filesIssue resolution1 year

Analytics Subprocessors

6.1 PostHog

AttributeDetails
Legal EntityPostHog, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsUS (us-east-1), EU (eu-central-1)
Customer Data ResidencyEU for Acme Cloud (product analytics)
Services UsedProduct analytics, session replay, feature flags
Processing PurposeUnderstanding product usage, improving user experience
Data Types ProcessedPseudonymized user identifiers, usage events, session data
Security CertificationsSOC 2 Type II
Transfer MechanismEU data residency selected (no transfer)
DPA StatusPostHog DPA incorporated
BAA AvailableUpon request
Engagement DateMarch 2024
Review DateMarch 2026 (annual)

Data Minimization Controls:

ControlImplementation
PseudonymizationUser IDs hashed before transmission
PII exclusionEmail, names excluded from analytics
SamplingSession replay sampling (10% of sessions)
Retention2-year analytics data retention

6.2 Sentry

AttributeDetails
Legal EntityFunctional Software, Inc. (dba Sentry)
HeadquartersSan Francisco, California, USA
Processing LocationsUS
Customer Data ResidencyUS (error data only)
Services UsedError tracking, performance monitoring
Processing PurposeApplication error detection, debugging
Data Types ProcessedError context, stack traces, user identifiers (optional)
Security CertificationsSOC 2 Type II, ISO 27001
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusSentry DPA incorporated
BAA AvailableYes
Engagement DateFebruary 2023
Review DateFebruary 2026 (annual)

Payment Subprocessors

7.1 Stripe

AttributeDetails
Legal EntityStripe, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsUS, EU, UK
Customer Data ResidencyPer card network requirements
Services UsedPayment processing, subscription billing, invoicing
Processing PurposeProcessing subscription payments, managing billing
Data Types ProcessedBilling contact, payment method tokens, transaction data
Security CertificationsPCI DSS Level 1, SOC 2 Type II, ISO 27001
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusStripe DPA incorporated
BAA AvailableN/A (payment processor)
Engagement DateJanuary 2022
Review DateJanuary 2026 (annual)

Payment Data Handling:

Data TypeProcessingStorage
Cardholder nameTokenized by StripeStripe only
Card numberNever touches Acme Cloud systemsStripe only (PCI DSS)
Billing addressStored for invoicingAcme Cloud database
Payment historyTransaction recordsAcme Cloud + Stripe

Authentication Subprocessors

8.1 Okta

AttributeDetails
Legal EntityOkta, Inc.
HeadquartersSan Francisco, California, USA
Processing LocationsUS, EU
Customer Data ResidencyPer customer workspace configuration
Services UsedSSO, MFA, user directory (Acme Cloud workforce only)
Processing PurposeEmployee authentication, access management
Data Types ProcessedAcme Cloud employee credentials (not Customer Personal Data)
Security CertificationsSOC 2 Type II, ISO 27001, FedRAMP
Transfer MechanismEU-US DPF (certified), SCCs
DPA StatusOkta DPA incorporated
BAA AvailableYes
Engagement DateJanuary 2022
Review DateJanuary 2026 (annual)

Note: Okta is used for Acme Cloud workforce identity only. Customer SSO is handled directly by Acme Cloud platform without Okta involvement.


Subprocessor Assessment Process

9.1 Pre-Engagement Assessment

Before engaging a new subprocessor, Acme Cloud conducts:

Assessment AreaEvaluation CriteriaDocumentation
Security postureSOC 2 or equivalent certificationCertification review
Privacy complianceGDPR/CCPA compliance, DPA availabilityDPA review
Data handlingProcessing scope, data residency, retentionTechnical documentation
Transfer mechanismsDPF certification, SCC availabilityLegal review
Contract termsDPA terms equivalent to our DPAContract review
Business viabilityFinancial stability, market positionBusiness assessment

9.2 Assessment Scoring

ScoreRisk LevelApproval Requirement
90-100LowPrivacy team approval
75-89MediumCPO approval
60-74HighCPO + CISO approval with controls
Below 60UnacceptableEngagement not permitted

9.3 Ongoing Monitoring

Monitoring ActivityFrequencyOwner
Security certification reviewAnnualGRC Team
DPA compliance checkAnnualPrivacy Team
Security questionnaireAnnualSecurity Team
Incident monitoringContinuousSecurity Operations
Breach notification monitoringContinuousPrivacy Team
Contract renewal reviewPer renewalLegal + Privacy

Change Notification Process

10.1 Notification Types

Change TypeNotice PeriodNotification Method
New subprocessor30 daysEmail to designated contact
Subprocessor replacement30 daysEmail to designated contact
Subprocessor removalInformational (no objection right)Email or Trust Center update
Processing scope change30 daysEmail to designated contact
Location change30 daysEmail to designated contact

10.2 Notification Content

Each notification includes:

ElementDescription
Subprocessor identityLegal name, headquarters
Processing purposeSpecific data processing activities
Data typesCategories of Personal Data processed
LocationsProcessing and storage locations
Effective dateWhen engagement becomes effective
Objection deadlineLast date to submit objection
Objection processHow to submit objection

10.3 Objection Process

Customers may object to new subprocessors:

Step 1: Written Objection 1.1. Submit objection in writing within notice period 1.2. State specific, reasonable data protection grounds 1.3. Propose alternatives if available

Step 2: Good Faith Resolution 2.1. Acme Cloud reviews objection 2.2. Parties discuss potential solutions 2.3. Acme Cloud may: address concerns, offer alternative configuration, or proceed

Step 3: Resolution Outcomes 3.1. If resolved, continue service with agreed modifications 3.2. If unresolved, Customer may terminate affected services 3.3. Termination right is exclusive remedy for objection

10.4 Subscription to Updates

Customers may subscribe to subprocessor updates:

Subscription MethodHow to Subscribe
Email notificationContact privacy@acmecloud.com with subscription request
Trust Center RSSSubscribe to Trust Center RSS feed
In-app notificationEnable Trust Center notifications in platform settings

Framework Mapping Appendix

Regulatory Subprocessor Requirements

RegulationRequirementAcme Cloud Implementation
GDPR Art. 28(2)Prior authorization30-day notice + objection right
GDPR Art. 28(4)Equivalent obligationsDPA flow-down to all subprocessors
UK GDPR Art. 28Same as GDPRSame implementation
LGPD Art. 39Subprocessor disclosurePublished list
CCPA 1798.140(ag)Written contractService provider contracts
SCCs Clause 9Prior notification30-day notice process

SOC 2 Mapping

SOC 2 CriteriaSubprocessor ControlEvidence
CC3.2Risk assessmentPre-engagement assessment
CC9.1Vendor managementAssessment process, monitoring
CC9.2Contract requirementsDPA, security terms
CC9.3Ongoing monitoringAnnual reassessment

ISO 27001 Mapping

ISO 27001 ControlSubprocessor ControlEvidence
A.15.1.1Supplier policyAssessment policy
A.15.1.2Supplier agreementsDPA, contracts
A.15.1.3Supply chain securitySecurity assessments
A.15.2.1Monitoring and reviewAnnual review process
A.15.2.2Change managementChange notification process

Current Subprocessor Summary Table

SubprocessorCategoryLocationData TypesTransfer Mechanism
Amazon Web ServicesInfrastructureUS, EU, UK, APACAll Customer DataDPF, SCCs
CloudflareInfrastructureGlobal (edge)Transient onlyDPF, SCCs
NeonDatabasePer AWS regionAll Customer DataDPF, SCCs
DatadogSecurityUSSecurity logsDPF, SCCs
CrowdStrikeSecurityUSEndpoint telemetryDPF, SCCs
SnykSecurityUSCode metadataDPF, SCCs
ResendCommunicationUSEmail dataDPF, SCCs
TwilioCommunicationUSSMS dataDPF, SCCs
SlackCommunicationUS, EUNotification contentDPF, SCCs
IntercomSupportUS, EUSupport dataDPF, SCCs
PostHogAnalyticsEUUsage dataEU residency
SentryAnalyticsUSError dataDPF, SCCs
StripePaymentUS, EUBilling dataDPF, SCCs
OktaAuthenticationUSWorkforce onlyDPF, SCCs

Related Trust Center documents

dpa, privacy policy, security overview, encryption standards, data retention

Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices
Last updated: January 15, 2026
EthicPages logoEthicPages